ATT&CK - 凭据访问

admin 2024年4月15日02:01:01评论4 views字数 688阅读2分17秒阅读模式

Credential Access

Credential access represents techniques that can be used by adversaries to obtain access to or control over passwords, tokens, cryptographic keys, or other values that could be used by an adversary to gain unauthorized access to resources. Credential access allows the adversary to assume the identity of an account, with all of that account's permissions on the system and network, and makes it harder for defenders to detect the adversary. With sufficient access within a network, an adversary can create accounts for later use within the environment.

凭据访问

凭据访问(Credential Access)表示攻击者使用的技术,这些技术用于获取或控制密码,令牌,加密密钥或其他可以被攻击者用来获取对资源的未授权访问的值。凭据访问权限允许攻击者获取帐户的身份,并拥有该帐户在系统和网络上的所有权限,并使防御者更难以检测到攻击者。利用对网络的足够的访问权限,攻击者可以创建帐户以供以后在该环境中使用。

- 译者: 林妙倩、戴亦仑 . source:cve.scap.org.cn

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2024年4月15日02:01:01
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   ATT&CK - 凭据访问https://cn-sec.com/archives/2657941.html

发表评论

匿名网友 填写信息